logo

Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack

ID: 43fc69cb-585e-53bc-b67e-90aff9aa678d

STIX ID: report--43fc69cb-585e-53bc-b67e-90aff9aa678d

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** The Telnyx Python SDK on PyPI was compromised by the threat actor TeamPCP—malicious releases (telnyx 4.87.1 and 4.87.2) were published and execute at import time, using WAV steganography to deliver platform-specific payloads that establish persistence, harvest secrets, and exfiltrate data to 83.142.209.203:8080; the advisory places this incident within a broader credential-chaining supply-chain campaign that has previously backdoored Trivy, npm packages, Checkmarx GitHub Actions, and LiteLLM. The report includes package SHA256 hashes, C2 IP/URLs, persistence artifacts, and actionable mitigations (remove malicious versions, rotate credentials, block outbound traffic to the C2, and audit CI/CD pipelines).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.